Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 171
  • Last Modified:

Splunk - receiving data from univ. forwarder

Hey experts! I am evaluating Splunk for a client. I have deployed the server piece and installed the universal forwarder onto a few Windows servers. I noticed the logs from these servers appeared to not be showing in search results.

I checked the splunkd file and the last line shows a successful connection to the Splunk server. During the install wizard of the univ forwarder, I just accepted the defaults.

Is there a configuration piece I am missing?
0
Schuyler Dorsey
Asked:
Schuyler Dorsey
  • 5
  • 2
1 Solution
 
Schuyler DorseyAuthor Commented:
FYI the Univ. Forwarder sends the App, System and Security logs by default.
0
 
Schuyler DorseyAuthor Commented:
I have an index created for wineventlog and msad. Just accepted defaults for these.
0
 
Schuyler DorseyAuthor Commented:
I think I got it. After rebooting the indexer, some logs are appearing in search results. Will monitor to confirm resolution.
0
VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

 
btanExec ConsultantCommented:
if you check the output.conf comments, it stated "# You must restart Splunk to enable configurations."

http://docs.splunk.com/Documentation/Splunk/6.2.1/Admin/Outputsconf

also it stated restart forwarder for some configuration changes.

http://docs.splunk.com/Documentation/Splunk/6.2.1/Forwarding/Deploymentoverview#General_configuration_issues
0
 
Schuyler DorseyAuthor Commented:
I fixed this by adjusting my inputs.conf. My stanzas had an error in them.
0
 
btanExec ConsultantCommented:
thanks for sharing hope my post has help though
0
 
Schuyler DorseyAuthor Commented:
Correct answer.
0

Featured Post

Evaluating UTMs? Here's what you need to know!

Evaluating a UTM appliance and vendor can prove to be an overwhelming exercise.  How can you make sure that you're getting the security that your organization needs without breaking the bank? Check out our UTM Buyer's Guide for more information on what you should be looking for!

  • 5
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now